Elearningfreak develops a web-based plugin for embedding Articulate content, a modestly represented but notably prominent tool in educational technology deployment. The vendor's vulnerability profile centers on application-layer input-handling and access-control weaknesses, with recurring issues including unrestricted file uploads, cross-site scripting, cross-site request forgery, improper authentication, and path traversal, typical of web-facing educational software that handles user-generated content and course materials. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Elearningfreak over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-5630HIGH The Insert or Embed Articulate Content into WordPress plugin before 4.3000000024 does not prevent authors from uploading arbitrary files to the site, which may allow them to upload | Jul 15, 2024 | 8.8 | 28 | NO | NO |
CVE-2019-15649HIGH The insert-or-embed-articulate-content-into-wordpress plugin before 4.2999 for WordPress has insufficient restrictions on file upload. | Aug 27, 2019 | 8.8 | 26 | NO | NO |
CVE-2019-15648MEDIUM The insert-or-embed-articulate-content-into-wordpress plugin before 4.29991 for WordPress has insufficient restrictions on deleting or renaming by a Subscriber. | Aug 27, 2019 | 6.5 | 21 | NO | NO |
CVE-2024-0757MEDIUM The Insert or Embed Articulate Content into WordPress plugin through 4.3000000023 is not properly filtering which file extensions are allowed to be imported on the server, allowing | Jun 4, 2024 | 5.4 | 19 | NO | NO |
CVE-2024-0756MEDIUM The Insert or Embed Articulate Content into WordPress plugin through 4.3000000023 lacks validation of URLs when adding iframes, allowing attackers to inject an iFrame in the page a | Jun 4, 2024 | 5.4 | 17 | NO | NO |
CVE-2023-50824MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brian Batt Insert or Embed Articulate Content into WordPress allows Stored XSS | Dec 21, 2023 | 5.4 | 16 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Elearningfreak.
Media articles that mention a CVE ID that affects a product developed by Elearningfreak — matched by CVE ID, not by vendor name.